What is CVE-2026-41940?
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Timeline
- 2026-04-29Published to the U.S. National Vulnerability Database (NVD)
- 2026-04-30Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-05-02First covered in a defend.network daily briefing
- 2026-05-03CISA federal remediation deadline (BOD 22-01)
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Affected product
WebPros CPanel & WHM And WP2 (WordPress Squared)
NVD also lists CPE entries for: Cpanel, Cpanel Whm, Cpanel Wp Squared
Remediation Steps
- Verify current cPanel version against CISA advisory and latest security releases
- Apply latest cPanel security patches before Sunday deadline enforced by federal agencies
- Review access logs for exploitation indicators and unauthorized configuration changes
- Reset all cPanel and database credentials after patching
- Implement WAF rules to block exploitation attempts during patch deployment
References
- https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
- https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
- https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cvedetails.com/cve/CVE-2026-41940
- https://nvd.nist.gov/vuln/detail/CVE-2026-41940
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of May 2026 (May 4 – 10)
- Checkmarx Jenkins compromise; AI-generated zero-day 2FA bypass (2026-05-12)
- cPanel & MOVEit exploited; RMM phishing hits 80+ organizations (2026-05-05)
- Linux root vulnerability in KEV; cPanel mass-exploitation continues (2026-05-04)
- cPanel RCE ransomware; 30K Facebook hacked; Trellix source leaked (2026-05-03)
- cPanel auth bypass; state token harvesting; SaaS extortion attacks (2026-05-02)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.